Privilege Escalation Vulnerability in SYS600 RBAC Mechanism by Hitachi Energy
CVE-2026-9854
8.5HIGH
What is CVE-2026-9854?
A critical flaw has been identified within the SYS600 Role-Based Access Control (RBAC) mechanism. This vulnerability allows users with access to engineering tools to elevate their permissions to an administrative level on the underlying Windows host. Consequently, affected users can gain full control over the host machine, posing significant security risks. Users are advised to update their systems to mitigate potential threats associated with this vulnerability.
Affected Version(s)
MicroSCADA SYS600 10.0 <= 10.7